Skip to content
Nenkin

KCMVP: Korea's Cryptographic Module Validation Programme

KCMVP, the Korean Cryptographic Module Validation Program, is South Korea’s national validation programme for cryptographic modules used by public institutions. It is distinct from Korea’s Common Criteria scheme (KECS) but is frequently tracked alongside CC certifications because both appear on security-product procurement lists.

Key facts

  • Authorizing body: National Security Research Institute (NSR), under the National Intelligence Service (NIS)
  • Country / region: Republic of Korea
  • Year established: 2005
  • Product types: cryptographic modules (software, hardware, firmware, hybrid) used in Korean public-sector systems
  • CCRA status: KCMVP is not a CCRA scheme; Korea’s CC authorizing scheme is KECS (operated by IT Security Certification Center, ITSCC)
  • Canonical portal: https://eng.nis.go.kr/EAF/1_7_2_1.do

Overview

KCMVP validates cryptographic modules against Korean standards (KS X ISO/IEC 19790 and national algorithm requirements), requiring that modules implement approved cryptographic algorithms such as ARIA, SEED, LEA, HIGHT, and Korean hash functions. It is a precondition for using a module in many Korean public systems.

How evaluations work under this scheme

Accredited Korean testing laboratories evaluate a submitted module against KCMVP criteria, verifying algorithm conformance, physical security (where applicable), self-tests, and key management. The NSR issues the validation certificate upon successful review. While KCMVP is conceptually comparable to FIPS 140-3 validation in the United States, the algorithms, thresholds, and administration are Korea-specific.

Notable product categories

  • Software cryptographic libraries for enterprise applications
  • Hardware security modules and cryptographic co-processors
  • Smart card cryptographic firmware
  • Mobile and embedded cryptographic modules for Korean public services

Relationship to CC baseline

KCMVP is not built on ISO/IEC 15408: it targets cryptographic module validation rather than TOE security evaluation. Products may carry both a KCMVP validation (for the cryptographic module) and a KECS CC certificate (for a broader TOE that embeds the module). NenkinTracker treats KCMVP records as a distinct programme so cryptographic module status is visible alongside CC claims.

Where to find official records

See also: Certification Schemes Overview, Glossary.

Frequently asked questions

What is KCMVP?
KCMVP is the Korean Cryptographic Module Validation Program, South Korea's national validation programme for cryptographic modules used by public institutions. It is operated by the National Security Research Institute (NSR) under the National Intelligence Service (NIS) and was established in 2005. KCMVP is the Korean equivalent of the U.S. FIPS 140-3 validation programme.
What does KCMVP validate?
KCMVP validates cryptographic modules: software, hardware, firmware, and hybrid modules used in Korean public-sector systems. Coverage includes software cryptographic libraries for enterprise applications, hardware security modules and cryptographic co-processors, smart card cryptographic firmware, and mobile and embedded cryptographic modules for Korean public services. KCMVP is a precondition for use in many Korean public systems.
Is KCMVP the same as Korea's CC scheme?
No. KCMVP is distinct from KECS, the Korean Common Criteria scheme. KECS is operated by the IT Security Certification Center (ITSCC) and is a CCRA Certificate Authorizing Member; it issues CC certificates for full TOEs. KCMVP, run by the NSR, validates only the cryptographic module. A product can hold both: a KECS CC certificate for the broader TOE and a KCMVP validation for the cryptographic module embedded inside it.
How is a KCMVP validation issued?
Accredited Korean testing laboratories evaluate a submitted module against KCMVP criteria, verifying algorithm conformance, physical security where applicable, self-tests, and key management. The framework follows KS X ISO/IEC 19790 alongside Korea-specific algorithm requirements. The NSR reviews the laboratory output and issues the validation certificate.
Which algorithms does KCMVP require?
KCMVP requires implementation of approved Korean cryptographic algorithms. These include the ARIA block cipher (a Korean national standard), SEED, the LEA lightweight block cipher, the HIGHT cipher, and Korean hash functions. The list is set by the NSR and is different from the FIPS-approved algorithm set used in the United States, which is one reason KCMVP and FIPS 140-3 are not interchangeable.
Is KCMVP a CCRA scheme?
No. KCMVP is not a CCRA scheme and is not built on ISO/IEC 15408. It is a cryptographic module validation programme rather than a TOE security evaluation framework. Korea's CCRA participation runs through KECS. Internationally, KCMVP is conceptually comparable to FIPS 140-3 but the algorithms, thresholds, and administration are Korea-specific and validations are not mutually recognised.